Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module implementing the classic SMB relay attack (MS08-068, CVE-2008-4037) against Microsoft Windows systems. The exploit acts as an SMB server, relaying authentication attempts from a victim to a target host. If the victim is an administrator on the target and SMB signing is not enforced, the module can execute arbitrary payloads (such as reverse shells or Meterpreter sessions) on the target system. The exploit supports multiple payload delivery methods, including PowerShell, native executable upload, MOF, and command execution. The attack is typically triggered by enticing the victim to access a malicious UNC path (e.g., \\ATTACKER_IP\SHARE). The module is weaponized, highly configurable, and leverages Metasploit's payload framework. The only code file is written in Ruby and is structured as a standard Metasploit exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.